| ¹ó ÖÝ Ñ§ ϰ Íø |
|
¡¡¡¡ÔÚÖÐСÐÍÒì¹¹ÍøÂçÖУ¬ºÜ¶àÓû§Ñ¡ÔñLINUX×÷ÎªÍøÂç²Ù×÷ϵͳ£¬ÀûÓÃÆä¼òµ¥µÄÅäÖúÍÓû§ÊìϤµÄͼÐνçÃæÌṩinternet·þÎñ£¬Ftp±ãÊÇÆäÌṩµÄ·þÎñÖ®Ò»¡£ÔÚÖÚ¶àÍøÂçÓ¦ÓÃÖУ¬ftp£¨Îļþ´«ÊäÐÒ飩ÓÐ×ŷdz£ÖØÒªµÄµØÎ»¡£»¥ÁªÍøÒ»¸öÊ®·ÖÖØÒªµÄ×ÊÔ´¾ÍÊÇÈí¼þ×ÊÔ´£¬¶ø¸÷ÖÖ¸÷ÑùµÄÈí¼þ×ÊÔ´´ó¶àÊý¶¼·ÅÔÚftp·þÎñÆ÷ÖС£Óë´ó¶àÊý»¥ÁªÍø·þÎñÒ»Ñù£¬ftpÒ²ÊÇÒ»¸ö¿Í»§»ú/·þÎñÆ÷ϵͳ¡£
¡¡¡¡ssh£¨secure shell£©ÊÇÒÔÔ¶³ÌÁª»ú·þÎñ·½Ê½²Ù×÷·þÎñÆ÷ʱµÄ½ÏΪ°²È«µÄ½â¾ö·½°¸¡£Ëü×î³õÓÉ·ÒÀ¼µÄÒ»¼Ò¹«Ë¾¿ª·¢£¬µ«ÓÉÓÚÊܰæÈ¨ºÍ¼ÓÃÜËã·¨µÄÏÞÖÆ£¬ºÜ¶àÈËת¶øÊ¹ÓÃÃâ·ÑµÄÌæ´úÈí¼þopenssh¡£ssh£¨secure shell£©ÊÇÒÔÔ¶³ÌÁª»ú·þÎñ·½Ê½²Ù×÷·þÎñÆ÷ʱµÄ½ÏΪ°²È«µÄ½â¾ö·½°¸¡£Ëü×î³õÓÉ·ÒÀ¼µÄÒ»¼Ò¹«Ë¾¿ª·¢£¬µ«ÓÉÓÚÊܰæÈ¨ºÍ¼ÓÃÜËã·¨µÄÏÞÖÆ£¬ºÜ¶àÈËת¶øÊ¹ÓÃÃâ·ÑµÄÌæ´úÈí¼þopenssh¡£ Óû§Í¨¹ýssh¿ÉÒÔ°ÑËùÓд«ÊäµÄÊý¾Ý½øÐмÓÃÜ£¬Ê¹¡°ÖмäÈË¡±µÄ¹¥»÷·½Ê½²»¿ÉÄÜʵÏÖ£¬¶øÇÒÒ²Äܹ»·ÀÖ¹dnsºÍipÆÛÆ¡£Ëü»¹ÓÐÒ»¸ö¶îÍâµÄºÃ´¦ÊÇ´«ÊäµÄÊý¾ÝÊǾ¹ýѹËõµÄ£¬¿ÉÒÔ¼Ó¿ì´«ÊäµÄËÙ¶È¡£ssh×÷Óù㷺£¬¼È¿ÉÒÔ´úÌætelnet£¬ÓÖ¿ÉÒÔΪftp¡¢pop£¬ÉõÖÁΪpppÌṩһ¸ö°²È«µÄ¡°Í¨µÀ¡±¡£sshÐÒéÔÚÔ¤ÉèµÄ״̬ÖУ¬ÌṩÁ½¸ö·þÎñÆ÷¹¦ÄÜ£ºÒ»¸öÊÇÀàËÆtelnetµÄÔ¶³ÌÁª»úʹÓÃshell·þÎñÆ÷£¬¼´Ë׳Æssh¹¦ÄÜ£»ÁíÒ»¸öÊÇÀàËÆftp·þÎñµÄsftp-server¹¦ÄÜ£¬¿ÉÌṩ¸ü°²È«µÄftp·þÎñ¡£ ¡¡¡¡sshµÄ°²È«ÑéÖ¤ÈçºÎ¹¤×÷ÄØ£¿Ö÷ÒªÒÀ¿¿Áª»ú¼ÓÃܼ¼Êõ¡£´Ó¿Í»§¶ËÀ´¿´£¬ÓÐÒÔÏÂÁ½ÖÖ°²È«ÑéÖ¤¼¶±ð£º ¡¡¡¡1£®»ùÓÚ¿ÚÁîµÄ°²È«ÑéÖ¤£¨ssh1£© Ö»ÒªÖªµÀ×Ô¼ºµÄÕ˺źͿÚÁ¾Í¿ÉÒԵǼµ½Ô¶³ÌÖ÷»ú¡£ËùÓд«ÊäµÄÊý¾Ý¶¼½«±»¼ÓÃÜ£¬µ«ÊDz»Äܱ£Ö¤ÕýÔÚÁ¬½ÓµÄ·þÎñÆ÷¾ÍÊÇÏëÒªÁ¬½ÓµÄ·þÎñÆ÷¡£¿ÉÄÜÊܵ½¡°ÖмäÈË¡±µÄ¹¥»÷¡£ ¡¡¡¡2£®»ùÓÚÃܳ׵ݲȫÑéÖ¤£¨ssh2£© ÐèÒªÒÀ¿¿Ãܳף¬¼´Óû§±ØÐëΪ×Ô¼º´´½¨Ò»¶ÔÃܳף¬²¢°Ñ¹«ÓÃÃܳ׷ÅÔÚÐèÒª·ÃÎʵķþÎñÆ÷ÉÏ¡£Èç¹ûÒªÁ¬½Óµ½ssh·þÎñÆ÷ÉÏ£¬¿Í»§¶ËÈí¼þ¾Í»áÏò·þÎñÆ÷·¢³öÇëÇó£¬ÇëÇóÓÃÃܳ׽øÐа²È«ÑéÖ¤¡£·þÎñÆ÷ÊÕµ½ÇëÇóÖ®ºó£¬ÏÈÔڸ÷þÎñÆ÷µÄhomeĿ¼ÏÂѰÕÒ¹«ÓÃÃܳף¬È»ºó°ÑËüºÍ·¢Ë͹ýÀ´µÄ¹«ÓÃÃܳ׽øÐбȽϡ£Èç¹ûÁ½¸öÃܳ×Ò»Ö£¬·þÎñÆ÷¾ÍÓù«ÓÃÃܳ׼ÓÃÜ¡°ÖÊѯ¡±£¨challenge£©£¬²¢°ÑËü·¢Ë͸ø¿Í»§¶ËÈí¼þ¡£¿Í»§¶ËÈí¼þÊÕµ½¡°ÖÊѯ¡±ºó£¬¾Í¿ÉÒÔÓÃ˽ÈËÃܳ׽âÃÜÔÙ°ÑËü·¢Ë͸ø·þÎñÆ÷¡£Ê¹ÓÃÕâÖÖ·½Ê½£¬Óû§±ØÐëÖªµÀ×Ô¼ºÃܳ׵ĿÚÁî¡£ÓëµÚÒ»ÖÖ¼¶±ðÏà±È£¬ÕâÖÖ¼¶±ð²»ÐèÒªÔÚÍøÂçÉÏ´«ËÍ¿ÚÁ²»½ö¼ÓÃÜËùÓд«Ë͵ÄÊý¾Ý£¬¶øÇÒ×èÖ¹ÁË¡°ÖмäÈË¡±¹¥»÷·½Ê½¡£opensshĿǰ´æÔÚÁ½¸ö°²È«ÒÅ»¼£º¿ÚÁî¡¢ÃÜ³×ÆÆ½â£¨ÀûÓÃ×ÖµäÎļþÈ¥½âÃÜÂ룩ºÍopensshÖпÉÄܱ»°²·ÅľÂí¡£ ¡¡¡¡Ò»¡¢srp¼ò½é ¡¡¡¡srpÈ«³Æ£ºsecure remote password£¨°²È«Ô¶³ÌÃÜÂ룩£¬ËüÊÇÒ»¸ö¿ª·ÅÔ´´úÂëÈÏÖ¤ÐÒ顣ʹÓÃsrpµÄ¿Í»§»ú/·þÎñÆ÷²»»áÔÚÍøÂçÉÏÒÔÃ÷ÎÄ»ò¼ÓÃܵķ½Ê½´«ËÍÃÜÂ룬ÕâÑù¿ÉÒÔÍêÈ«Ïû³ýÃÜÂëÆÛÆÐÐΪ¡£±£Ö¤¿ÚÁî¿ÉÒÔ°²È«µØÔÚÍøÂçÉÏÃæ´«ËÍ¡£»ù±¾µÄ˼ÏëÊÇ£¬·ÀÖ¹Óб»¶¯»òÖ÷¶¯ÍøÂçÈëÇÖÕßʹÓÃ×ֵ乥»÷¡£standford´óѧ¼ÆËã»úϵ¿ª·¢ÁËsrpÈí¼þ°ü£¬Ìṩ»ùÓÚ¿ÚÁîÈÏÖ¤ºÍ»á»°¼ÓÃܵݲȫ»úÖÆ£¬¶ø²»ÐèÒªÓû§»òÕßÊÇÍø¹Ü²ÎÓëÃÜÔ¿µÄ¹ÜÀí»ò·Ö·¢¡£srpΪÿһ¸öÈËÌṩ͸Ã÷µÄÃÜÂ밲ȫ£¬¶øÃ»ÓÐÆäËû°º¹óµÄÆðʼ¿ªÏú£¬±ÈÈç×èÖ¹ÆäËû°²È«Ì×¼þÈí¼þµÄʹÓõȡ£²»ÏñÆäËûµÄ°²È«Èí¼þ£¬srpÌ×¼þÊÇÒ»¸öÍêÈ«µÄʵÏÖÃÜÂëÈÏÖ¤µÄÈí¼þ°ü£¬²»ÊÇÁÙʱµÄ½â¾ö·½°¸¡£ºÍ±ê×¼µÄ/etc/shadow-style °²È«±È½Ï£¬srpÔÚÿһ¸ö·½Ãæ¶¼ÊDZȽϺõġ£Ê¹ÓÃsrp¶ÔÓû§ºÍ¹ÜÀíÕß¶¼ÓÐÒÔϵĺô¦£º ¡¡¡¡srpµÖÖÆ¡°password sniffing¡±£¨¿ÚÁî¼àÌý£©¹¥»÷¡£ÔÚÒ»¸öʹÓÃsrpÈÏÖ¤µÄ»á»°ÖУ¬¼àÌýÕß²»»á¼àÊÓµ½ÈκÎÔÚÍøÂçÖд«Ë͵ĿÚÁî¡£ÔÚÔ¶³ÌµÇ½Èí¼þÖУ¬Ã÷ÎĵÄÃÜÂë´«ËÍÊÇ×î´óµÄ°²È«Â©¶´¡£ÈκÎÈË¿ÉÒÔÓÃÒ»¸ö¼òµ¥µÄÐá̽Æ÷£¨sniffer£©¹¤¾ßµÃµ½ÄãµÇ½µ½Ô¶³ÌϵͳµÄÃÜÔ¿¡£ ¡¡¡¡¶þ¡¢Èí¼þÏÂÔØºÍ±àÒë ¡¡¡¡srpÈí¼þÖ÷Ò³ÊÇ£ºhttp://srp.stanford.edu ×îа汾2.1.1£¬°²×°srpǰÏÈÒª°²×°openssl¡£ #wget http://srp.stanford.edu/source/srp-2.1.1.tar.gz #cp /usr/src/redhat/sources #./configure --with-openssl=/usr/src/redhat/sources/openssl-0.9.6 \ --with-pam #make£»make install
¡¡¡¡epsÈ«³Æ£ºexponential password system£¨Ö¸ÊýÃÜÂëϵͳ£©£¬srpÈí¼þ°üÖÐÒѾ°üÀ¨epsÔ´´úÂë¡£ ¡¡¡¡1. °²×°pamÄ£¿é ¡¡¡¡pam¼ò½é£º ¡¡¡¡pamÈ«³Æ£ºpluggable authentication module £¨Ç¶ÈëʽÈÏ֤ģ¿é£©¡£Ëü×î³õÓÐSUN¹«Ë¾¿ª·¢£»ºÜ¿ì±»linuxÉçÇøµÄ½ÓÊÜ£¬²¢ÇÒ¿ª·¢Á˸ü¶àµÄÄ£¿é¡£ÆäÄ¿±êÊÇÌṩһÌ׿ÉÓÃÓÚÑéÖ¤Óû§Éí·ÝµÄº¯Êý¿â£¬´Ó¶ø½«ÈÏÖ¤´ÓÓ¦ÓóÌÐò¿ª·¢ÖжÀÁ¢³öÀ´¡£linux-pam´¦ÀíËÄÖÖ¶ÀÁ¢µÄ£¨¹ÜÀí£©¹¤×÷¡£ËüÃÇÊÇ£º ÈÏÖ¤¹ÜÀí£» ÕʺŹÜÀí£» »á»°ÆÚ¼ä¹ÜÀí£»ºÍÃÜÂë¹ÜÀí¡£amxSb/WJefcB8][ ´ËÎÄתÌùÓÚÎÒµÄÑ§Ï°ÍøµçÄÔ¿ÎÌÃLINUX½Ì³Ì http://www.Gzu521.com]amxSb/WJefcB8] ¡¡¡¡pam¹¤×÷·½Ê½£º ¡¡¡¡£¨1£© µ÷ÓÃij¸öÓ¦ÓóÌÐò£¬ÒԵõ½¸Ã³ÌÐòµÄ·þÎñ¡£ ¡¡¡¡£¨2£© pamÓ¦ÓóÌÐòµ÷Óúǫ́µÄpam¿â½øÐÐÈÏÖ¤¹¤×÷¡£ ¡¡¡¡£¨3£© pam¿âÔÚ/etc/pam.d/Ŀ¼ÖвéÕÒÓйØÓ¦ÓóÌÐòϸ½ÚµÄÅäÖÃÎļþ,¸ÃÎļþ¸æËßpam,±¾Ó¦ÓóÌÐòʹÓúÎÖÖÈÏÖ¤»úÖÆ¡£ ¡¡¡¡£¨4£© pam¿â×°ÔØËùÐèµÄÈÏ֤ģ¿é¡£ ¡¡¡¡£¨5£© ÕâЩģ¿é¿ÉÒÔÈÃpamÓëÓ¦ÓóÌÐòÖеĻỰº¯Êý½øÐÐͨÐÅ¡£ ¡¡¡¡£¨6£© »á»°º¯ÊýÏòÓû§ÒªÇóÓйØÐÅÏ¢¡£ ¡¡¡¡£¨7£© Óû§¶ÔÕâЩҪÇó×ö³ö»ØÓ¦£¬ÌṩËùÐèÐÅÏ¢¡£ ¡¡¡¡£¨8£© pamÈÏ֤ģ¿éͨ¹ýpam¿â½«ÈÏÖ¤ÐÅÏ¢Ìṩ¸øÓ¦ÓóÌÐò¡£ ¡¡¡¡£¨9£© ÈÏÖ¤Íê³Éºó£¬Ó¦ÓóÌÐò×ö³öÁ½ÖÖÑ¡Ôñ£º ¡¡¡¡½«ËùÐèȨÏÞ¸³ÓèÓû§£¬²¢Í¨ÖªÓû§¡£ ¡¡¡¡ÈÏ֤ʧ°Ü£¬²¢Í¨ÖªÓû§¡£ ¡¡¡¡pam¹¤×÷Á÷³Ì¼ûͼ1¡£
ͼ1 pam¹¤×÷Á÷³Ì ¡¡¡¡pam¾ßÌåʹÓ÷½·¨£º #cd /usr/src/redhat/sources/srp-2.1.1/base/pam_eps. #install -m 644 pam_eps_auth.so pam_eps_passwd.so /lib/security
¡¡¡¡2. ʹÓÃeps pamÄ£¿é½øÐÐÃÜÂëÑéÖ¤ ¡¡¡¡£¨1£© Ê×Ïȱ¸·Ý /etc/pam.d/system-authÎļþ ¡¡¡¡£¨2£© ÐÞ¸Ä /etc/pam.d/system-authÎļþÈçÏÂÐÎʽ£º auth required /lib/security/pam_unix.so likeauth nullok md5 shadow auth sufficient /lib/security/pam_eps_auth.so auth required /lib/security/pam_deny.so account sufficient /lib/security/pam_unix.so account required /lib/security/pam_deny.so password required /lib/security/pam_cracklib.so retry=3 password required /lib/security/pam_eps_passwd.so password sufficient /lib/security/pam_unix.so nullok use_authtok md5 shadow lw&R8{LKz_ @[±¾_ÎÄ_À´_Ô´_ÓÚ_ÎÒ_µÄ_ѧ_ϰ_ÍøµçÄÔ¿ÎÌÃLINUX½Ì³Ì http://Www.GZU521.Com ]lw&R8{LKz_ @ password required /lib/security/pam_deny.so session required /lib/security/pam_limits.so session required /lib/security/pam_unix.so
¡¡¡¡×¢ÒâÉÏÃæµÚÒ»ÐкÚÌå×Ö±íʾpamµÄeps_authÄ£¿é¿ÉÒÔÂú×ãÈÏÖ¤ÐèÇó¡£µÚ¶þÐкÚÌå×Ö±íʾpam µÄpam_eps_passwd.so Ä£¿éÓÃÀ´½øÐÐÃÜÂë¹ÜÀí¡£ ¡¡¡¡£¨3£© ½«±ê×¼ÃÜÂëת»»Îªeps¸ñʽ ¡¡¡¡£¨4£© /etc/pam.d/system-auth ÅäÖÃÎļþµÄÄ£¿épam_eps_passwd.so ½«eps°æ±¾µÄÃÜÂëÑéÖ¤×Ö·û´®Ð´Èë/etc/tpasswd ÎļþÖС£ ÐÞ¸Ä /etc/pam.dpasswdÎļþÈçÏÂÐÎʽ£º auth required /lib/security/pam_stack.so service=system-auth account required /lib/security/pam_stack.so service=system-auth password required /lib/security/pam_stack.so service=system-auth
¡¡¡¡£¨1£©½øÈësrpÔ´´úÂëftp×ÓĿ¼£¬·Ö±ð½¨Á¢ftp·þÎñÆ÷ÎļþºÍftp¿Í»§¶ËÎļþ£º #cd /usr/src/redhat/sources/srp-2.2.1/ftp #make£»make install
service ftp { socket_type = stream wait = no user = root server = /usr/local/sbin/ftpd log_on_success += duration userid log_on_failure += userid nice = 10 disable = no }
#killall -usr1 xinetd
#%pam-1.0 k2@H0R?dkCocUlX€& [´Ë×ÊÁÏתÌùÓÚÑ§Ï°ÍøµçÄÔ¿ÎÌÃLINUX½Ì³Ì ]http://www.Gzu521.Comk2@H0R?dkCocUlX€& auth required /lib/security/pam_listfile.so item=user \ sense=deny file=/etc/ftpusers onerr=succeed auth required /lib/security/pam_stack.so service=srp-ftp auth required /lib/security/pam_shells.so account required /lib/security/pam_stack.so service=srp-ftp session required /lib/security/pam_stack.so service=srp-ftp $$ /usr/local/bin/ftp localhost connected to localhost.intevo.com. 220 k2.intevo.com ftp server (srpftp 1.3) ready. srp accepted as authentication type. name (localhost:kabir): cao srp password: xxxxxxxx srp authentication succeeded. using cipher cast5_cbc and hash function sha. 200 protection level set to private. 232 user kabir authorized by srp. 230 user kabir logged in. remote system type is unix. using binary mode to transfer file ¡¡¡¡Èç¹ûÏ£ÍûÔÚÆäËûlinux¼ÆËã»úʹÓÃftpµÇ¼µ½srp·þÎñÆ÷£¬ÐèÒª°²×°srp·þÎñÖ§³ÖºÍsrp¿Í»§»úÈí¼þ¡£·½·¨ÊǺÍÔÚsrp·þÎñÆ÷¶ËÏàͬµÄ¡£ none (1) blowfish_ecb (2) blowfish_cbc (3) blowfish_cfb64 (4) blowfish_ofb64 (5) cast5_ecb (6) cast5_cbc (7) cast5_cfb64 (8) cast5_ofb64 (9) des_ecb (10) des_cbc (11) des_cfb64 (12) des_ofb64 (13) des3_ecb (14) des3_cbc (15) des3_cfb64 (16) des3_ofb64 (17)
#/usr/local/bin/ftp -c blowfish_cfb64 ¡°ipµØÖ·¡±
#/usr/local/bin/ftp ¨Ch md5 ¡°ipµØÖ·¡±
¡¡¡¡Îå¡¢ÔÚ·Çlinuxƽ̨ÉÏʹÓÃsrp¿Í»§»ú ¡¡¡¡srpͬÑùÖ§³ÖÆäËûÁ÷ÐеIJÙ×÷ϵͳ£¨unix¡¢bsd¡¢winodws¡¢macos£©¡£kermit 95ÊÇÒ»¸ö¹¤×÷ÔÚwindows 9x, me, nt, and 2000, xpºÍ os/2²Ù×÷ϵͳϵÄsrp¿Í»§»ú¡£ÏêϸÇé¿öǰ²é¿´Ïà¹ØÍøÖ·£ºhttp://www.columbia.edu/kermit/k95.html ¡£ ¡¡¡¡×ܽ᣺ÏêϸµÄsrp¹¤×÷ÔÀí¿ÉÒÔÔÚsrpµÄÓйØÕ¾µã·¢ÏÖ¡£µØÖ·ÊÇhttp://srp.stanford.edu/srp£¬ÔÚÕâÀïÄã¿ÉÒԵõ½ÓйØÐÒéµÄÔÚÏß˵Ã÷http://srp.standford.edu/srp/design.html»òÕßÊÇÒ»¸ö³ö°æµÄ¹ØÓÚsrpµÄ¼¼Êõ°×ƤÊéhttp://srp.standford.edu/srp/ftp¡£ ÒÔÉÏÌṩÁËÏà¶Ôopenssh¸ü¼Ó°²È«¿ì½ÝµÄftpµÇ¼Զ³Ìlinux·þÎñÆ÷µÄ·½·¨£¬»ùÓÚsrp·þÎñ ftpÓ¦ÓÃÓëÆäËûÍøÂçÓ¦ÓÃÒ»ÑùÊôÓÚ¿Í»§»ú/·þÎñÆ÷Ä£ÐÍ£¬Ò»µ©Á¬Í¨ºó£¬¿Í»§»ú¿ÉÒÔÏíÓзþÎñÆ÷ËùÌṩµÄÒ»ÇзþÎñ¡£ |
ÔðÈα༣ºgzu521
| µçÄÔ¿ÎÌ÷ÖÀà | ||||||||||||||||
|
||||||||||||||||